Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6257 - Security Advisory
Issued:
2023-11-08
Updated:
2023-11-08

RHSA-2023:6257 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.13.21 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.13.21 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.13.21. There are no RPM packages for this update.

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (Rapid Reset Attack) (CVE-2023-39325)

A Red Hat Security Bulletin which addresses further details about the Rapid Reset flaw is available in the References section.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:562c214e9662e3684ac5b8c3d5d2759a83f544da8897a00ebe91a02fcad6d2d9

(For s390x architecture)
The image digest is sha256:31eb6fe82af60cf8693bf986d6db6d26cbb26950eb63401b2e6c2c19eb54c2b6

(For ppc64le architecture)
The image digest is sha256:0cc5f401894fafcf40653ff631edce27297f598546235e6107e100f9b4798f3a

(For aarch64 architecture)
The image digest is sha256:f0c0bad639693279314010424aba2abb76ba5f8f45ff1b40d4f8936c589e2e0e

All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • OCPBUGS-11604 - addon-agent, klusterlet, proxy-agent containers are not pinned to mgmt cores - no WLP annotation
  • OCPBUGS-11926 - hub side lookup function on managed cluster itself for policy templating should be allowed
  • OCPBUGS-13330 - OCP 4.13 | NTO profile's default parameter workloadHints.perPodPowerManagement = false seems to be hitting kernel taint bit 2 in nodes using x86_energy_perf function
  • OCPBUGS-14344 - TALM does not consider namespace of managed policies
  • OCPBUGS-18284 - On an SNO DU some of the test workload pods get restarted due to failed probes when leaving the node running for multiple days
  • OCPBUGS-18468 - Upgrade Recovery Fails on etcd Redeployment
  • OCPBUGS-18698 - TC bug: VFS allocated for dpdk Validate HugePages should allocate the amount of hugepages requested
  • OCPBUGS-22299 - [Azure] EgressIP cannot be applied to the egress node on Azure private cluster
  • OCPBUGS-22333 - duplicate entry in spec.plugins will cause console panic
  • OCPBUGS-22390 - Remove wildfly docker.io samples
  • OCPBUGS-22402 - CI fails because it pulls "openshift/origin-node" from Docker Hub and gets rate-limited
  • OCPBUGS-22412 - Bootstrap-unit tests are failing for the 4.13 branch
  • OCPBUGS-2812 - TALM does not enforce subscriptions when catalogsource is updated and both policies are in the same CGU
  • OCPBUGS-7652 - cluster-proxy-service-proxy pod is not pinned to mgmt cores - no WLP annotation

CVEs

  • CVE-2023-39325

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

aarch64

openshift4/cloud-network-config-controller-rhel8@sha256:3810956951c1988979ac24659c56ba6ec17e09054b6ce85abc4b14e670fc9cf6
openshift4/ose-cluster-authentication-operator@sha256:15edf4f6aeb81ceebe39ea705222b216bded95d01fe8bfce4d91b97b369c4ce5
openshift4/ose-cluster-ingress-operator@sha256:435ca54c6bada76ec200d0420b62bdd40890fb879c8c99e60a76c5d353cddfc0
openshift4/ose-cluster-kube-controller-manager-operator@sha256:075a470799eee154d399f32fe6b87c0a574a45ca97075da0356a88bf52695cd5
openshift4/ose-cluster-monitoring-operator@sha256:0905ecceec6ddbf5943fec3dc8857833fb7e2b54abc019a8304a8ef8925f61ce
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:b88672bc0fbdbfc98eb2416ec096cfed3efd9e255ffa96570cf600d09a69b0d9
openshift4/ose-cluster-samples-operator@sha256:de34b48dcb344803b70341a10bae3d42183d671b9cd5a7f5d4f50df68a7af639
openshift4/ose-console-operator@sha256:793343bd5bc4281551358642c332efc5a63fdc215f2861ef008cde6c2c9bdc4e
openshift4/ose-coredns@sha256:4e91f3c3a5734b9b0d5d4129d4ef251ca65e0c3d5a2c3547e5317078da9747c9
openshift4/ose-haproxy-router@sha256:0fd5109745b5eae7bda3edb0b264bd8f33192e0b048eba1abc49afb51e48001d
openshift4/ose-insights-rhel8-operator@sha256:f08b5cb6fdacf0cb78b014abf1f97843cc56df68db295bb418e16c5e3d94961c
openshift4/ose-machine-config-operator@sha256:14e76b91414aab129708a12432268e38e75408c7e9868559d55278a18532113d
openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:066495402b5fe2c12fd09063e4b6e99a621d5647a8c791902960b5debe9f9697
openshift4/ose-prometheus@sha256:434d54ba63921a763e12bc268ffe8def1e9675d3a8305598b4eb657beba3a978
openshift4/ose-prometheus-alertmanager@sha256:a87881f489d8c3cb8272c31c8ce2a0ca24ce85266d22548dd839e2521543e7e9
openshift4/ose-prometheus-node-exporter@sha256:06162dfcc7c9e7de786c04f172786c232407957c62b6b31627714b31b143e6ff

ppc64le

openshift4/cloud-network-config-controller-rhel8@sha256:3b3a2a764de073fc154cf4e857a369c91ecfb5e6c42a6f0e099c5c50b332dd27
openshift4/ose-cluster-authentication-operator@sha256:75d6d6e228c8db448712c8c4ce7463cd8978de42545a1ae2a3664475375d46ff
openshift4/ose-cluster-ingress-operator@sha256:997535dfc8ab47df6c357f39b9981c4f4d4538c67af3ac7206d8407105e3b218
openshift4/ose-cluster-kube-controller-manager-operator@sha256:7d33159b415e073ed2b526510ac416867381a466256c0c9511c00aecf039ec76
openshift4/ose-cluster-monitoring-operator@sha256:9aa3df1ff21ded9e06d3c1c71450e046ea40a32b4289b8bf33b448543606ef83
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:df712d87dbe3c49b18a605b01336697d816168127353252568e33023ce1e66e9
openshift4/ose-cluster-samples-operator@sha256:bad3770097f6a0c9654d8f9638d7d204e0ddfe860b16f7edbfc790ac8aa905a3
openshift4/ose-console-operator@sha256:b41a38296f075671e1807d781bd82eacd70568e90b38fdc20e51443f0bc0751f
openshift4/ose-coredns@sha256:109df33cddc4424fad9ad3c5a0fbbc4f94290144485ef08cdc529582efbc78c1
openshift4/ose-haproxy-router@sha256:d51da0731604e8b6d0dffa1a5ad0d6cb856ffa66d3c57f2e48d94a9d3fd97716
openshift4/ose-insights-rhel8-operator@sha256:6d2b4b9093a1cd622a77f31732a3314ea547c3dc906f55efbb9692ba592ad8d7
openshift4/ose-machine-config-operator@sha256:c44d276a26c1e864a33a0fad7930ed387dec54670be106459c8cbbfd62278306
openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:106f0186683403b7a567401bddeb3c5b571052f0cfdcb85765d5a09e88d4f2b7
openshift4/ose-prometheus@sha256:3a6d30d305fb9238cc462d309da1336dd8d5d62b8cf431162f0e2d0afcf867de
openshift4/ose-prometheus-alertmanager@sha256:07dc29a5e52c0023c6371dbba7bcda8cb008ade9073685be879b07e98b116e42
openshift4/ose-prometheus-node-exporter@sha256:625310d087b40ca40265b4d4810861fff36e00427c3c46f7b58278ffcf83f237

s390x

openshift4/cloud-network-config-controller-rhel8@sha256:ce7b75eeb28e81e488f12c8836d3e5bd3d9311ff714ee9202d051a473ec0fa9f
openshift4/ose-cluster-authentication-operator@sha256:8a5b24356f618c9c5794cb2881c3805e7cf9bd79f95f9694ac0977505695cef2
openshift4/ose-cluster-ingress-operator@sha256:252dc8ba3414ac50ff56b14900808ada31f102afa0ccd684a0066d369bd989e7
openshift4/ose-cluster-kube-controller-manager-operator@sha256:4534b5c675e52f1b2aca7802d00717550521f3ed9b134305c85e8846a7d038ab
openshift4/ose-cluster-monitoring-operator@sha256:3dc231bf8ffeecbfea375ac3fed0eb2892b4cafe670e9b86b3af393154213b46
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:af96509b3a7f7337c3dfd538d0e641751c9df4082b8c0cf49952d320f94611c7
openshift4/ose-cluster-samples-operator@sha256:5a080507be49f8c9813787b678a6162281ae79961d2030b5736f472902f5bdfe
openshift4/ose-console-operator@sha256:6eaad54d3c0ce20aa9e614fb6c9cdbe85bb670fe7fbf1cb4746853d8a732108b
openshift4/ose-coredns@sha256:0770efc5e323e64d95a8b7d79f323e17cc107368b12e2e8180646fed1698ffc8
openshift4/ose-haproxy-router@sha256:185d6b46be9aa0ac9b416169b30a731446b9d3be355f9ba5824dec7af6a88ffd
openshift4/ose-insights-rhel8-operator@sha256:d5c56aab8cc3ba6145f45dcc4a23391a6df4401eb6ec2309c390937ab6cdfa8b
openshift4/ose-machine-config-operator@sha256:94e3acab7e628f0e655798164ade645680a69a7fdc2ba8b2b2fcf988667ad000
openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:f3388d4c3ca2eda8e260cd931de76f43a3416383362bc0da1ce374ad06561959
openshift4/ose-prometheus@sha256:705e668cb406bed1cd0a633028abb1ad4cd7a76199763cd789daaef413ca5bfb
openshift4/ose-prometheus-alertmanager@sha256:f2310bc059ae0f26a98c060c3b0f75f9a7d903f5a8638fd0d85685b49a9fe03d
openshift4/ose-prometheus-node-exporter@sha256:a3cd65a87781cd07297f56e1595320b8fcdad6d2b4b13f4b433a1d25d48399de

x86_64

openshift4/cloud-network-config-controller-rhel8@sha256:d4dfbb9e94e39d2f9e5542367a04cadce0ca5f7dfd9b15c5f2a97fd30688af2b
openshift4/ose-cluster-authentication-operator@sha256:0ccc78a5bee86470de92084ef0d667741d4a342f89907083d66f1b8fb7fed3ff
openshift4/ose-cluster-ingress-operator@sha256:33bc668e23d4d3ebb5f9fed08c14663a37a483ddfe5426158ca73e5900623c7d
openshift4/ose-cluster-kube-controller-manager-operator@sha256:81a751470151e47c1e3596aa358378fdaa1d1a6859f21bbf7aab85fd822fb889
openshift4/ose-cluster-monitoring-operator@sha256:cd6c6c190e7a6ef119ba79c515471e3fe76dc5cceece7310dc6a16d9e11702e3
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:d303a79d60b0b9a87c7e7f2a816c1551b50a932c7b12e457e609c8b1106935dd
openshift4/ose-cluster-samples-operator@sha256:84dd81dd91328854d02a2a2f445079a05df2cb57725134586f9c8d4da97bde70
openshift4/ose-console-operator@sha256:e119c0c2980dc67aa69ba7460fbf849adf55f3096abd8255d6d11b609317a303
openshift4/ose-coredns@sha256:487cf44ab2c299e7cbe0f9e6d4ddd1fcd6bc8256d4ac468092fd58fc7b961e4d
openshift4/ose-haproxy-router@sha256:9dc44b904c260953c2e87bfb0581005179d1e22c03908fc248b1cedeb0ece79b
openshift4/ose-insights-rhel8-operator@sha256:dcb637f76dbe940890eb0960a358f8237414fccbf50c33bb1b317c327f96fe8f
openshift4/ose-machine-config-operator@sha256:28869cebbf8e5454493def0e6c8eb9bf33bfd8d56d1ce106a6c6708530c2c1c2
openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:e3023caa9323d2e82850fbc08cf7e088922da744dfda5f311b8fde22cdfa5fae
openshift4/ose-prometheus@sha256:4351a8d0cc3d8aecdf36b3e1818258e36474eff7605a474dee95307026bb2f8c
openshift4/ose-prometheus-alertmanager@sha256:d0f302c2463ddb16c08a04f191dac57668dda2d2db5fdef3194e96f5ae05547d
openshift4/ose-prometheus-node-exporter@sha256:f4fcf59199f172cf0accd38331f7c249d46de59952abfec49dbc952cf3fa2f95

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility